·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª

°ä²¼¹¦·ò 2023-11-20
1¡¢·áÌï½ðÈÚ·þÎñ¹«Ë¾Ôâµ½Medusa¹¥»÷²¢±»ÀÕË÷800ÍòÃÀÔª


¾ÝýÌå11ÔÂ16ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬ £¬·áÌï½ðÈÚ·þÎñ¹«Ë¾(TFS)Ôâµ½¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ £¬ÆäÔÚÅ·Ö޺ͷÇÖÞµÄϵͳÉϼì²âµ½Î´¾­ÊÚȨµÄ½Ó¼û¡£¡£¡£¡£¡£ ¡£¡£¡£ÀÕË÷ÍÅ»ïMedusaÒѽ«TFSÁÐÈëÆäÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬ £¬²¢ÀÕË÷800ÍòÃÀÔªÒÔɾ³ýÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß»¹¸øÁË·áÌï10ÌìµÄ¹¦·ò×ö³ö»ØÓ¦£¬£¬£¬ £¬£¬£¬£¬ £¬²¢Äܹ»Ñ¡ÔñÑÓ³Ö¾ÃÏÞ£¬£¬£¬ £¬£¬£¬£¬ £¬Ö»ÓÐÿÌìÖ§¸¶10000ÃÀÔª¡£¡£¡£¡£¡£ ¡£¡£¡£ÎªÁËÖ¤Ã÷ÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬ £¬ºÚ¿ÍMedusa°ä²¼ÁËÔ̺¬²ÆÕþÎļþ¡¢µç×Ó±í¸ñºÍ²É°ì·¢Æ±µÈÊý¾ÝµÄÑù±¾¡£¡£¡£¡£¡£ ¡£¡£¡£´óÎÞÊýÎļþ¶¼ÊǵÂÓ£¬£¬ £¬£¬£¬£¬ £¬Åú×¢ºÚ¿Í³É¹¦½Ó¼ûÁË·áÌïÖÐÅ·ÒµÎñµÄϵͳ¡£¡£¡£¡£¡£ ¡£¡£¡£×êÑÐÈËԱй©£¬£¬£¬ £¬£¬£¬£¬ £¬Õâ´Î¹¥»÷¿ÉÄÜÓëCitrix GatewayµÄ·ì϶Óйء£¡£¡£¡£¡£ ¡£¡£¡£


https://securityaffairs.com/154319/data-breach/toyota-financial-services-medusa-ransomware.html


2¡¢ÑÅÂí¹þ·ÆÂɱö·Ö¹«Ë¾±»INC¹¥»÷Ô¼37GBµÄÊý¾Ýй¶


¾Ý11ÔÂ17ÈÕ±¨Â·£¬£¬£¬ £¬£¬£¬£¬ £¬ÑÅÂí¹þÆû³µ·ÆÂɱöĦÍгµÔì×÷·Ö¹«Ë¾(YMPH)Ôâµ½¹¥»÷£¬£¬£¬ £¬£¬£¬£¬ £¬²¿ÃÅÔ±¹¤ÐÅϢй¶¡£¡£¡£¡£¡£ ¡£¡£¡£YMPHÓÚ10ÔÂ25ÈÕ³õ´Î·¢ÏÖÎÊÌ⣬£¬£¬ £¬£¬£¬£¬ £¬Æäһ̨·þÎñÆ÷Ô⵽δ¾­ÊÚȨµÄ½Ó¼û£¬£¬£¬ £¬£¬£¬£¬ £¬Ä¿Ç°ÔÚÆÀ¹ÀÕâ´Î¹¥»÷Ó°ÏìµÄÁìÓò¡£¡£¡£¡£¡£ ¡£¡£¡£ÀÕË÷ÍÅ»ïINCÐû³Æ¶Ô´ËÊÂÕÆ¹Ü£¬£¬£¬ £¬£¬£¬£¬ £¬ÓÚ11ÔÂ15ÈÕ½«¸Ã¹«Ë¾Ôö³¤µ½ÆäÍøÕ¾¡£¡£¡£¡£¡£ ¡£¡£¡£¶ûºó°ä²¼Á˶à¸öÎļþ£¬£¬£¬ £¬£¬£¬£¬ £¬ÆäÖÐÔ̺¬Ô¼Äª37GBµÄÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬ £¬Éæ¼°Ô±¹¤IDÐÅÏ¢¡¢±¸·ÝÎļþÒÔ¼°¹«Ë¾ºÍÏúÊÛÐÅÏ¢µÈ¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.bleepingcomputer.com/news/security/yamaha-motor-confirms-ransomware-attack-on-philippines-subsidiary/ 


3¡¢BGRSºÍSIRVAÔâ¹¥»÷µ¼Ö¼ÓÄôóÊÐÕþ»ú¹¹´óÁ¿Ô±¹¤ÐÅϢй¶


¼ÓÄô󵱾ÖÔÚ11ÔÂ19ÈÕÅû¶Á˽üÆÚµÄÒ»´ÎÊý¾Ýй¶ÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬ £¬Ó°ÏìÁËÏÖÈκÍǰÈι«¹²·þÎñ²¿ÃÅÔ±¹¤ÒÔ¼°¼ÓÄôó»Ê¼ÒÆï¾¯ºÍ¼ÓÄôóÎä×°¶ÓÁгÉÔ±¡£¡£¡£¡£¡£ ¡£¡£¡£Ä¿Ç°È·¶¨£¬£¬£¬ £¬£¬£¬£¬ £¬ÎªÔ±¹¤Ìṩ°áǨ·þÎñµÄBrookfield Global Relocation Services(BGRS)ºÍSIRVA Worldwide Relocation & Moving ServicesÊÇÕâ´ÎÊý¾Ýй¶ÊÂÎñµÄÔ´Í·¡£¡£¡£¡£¡£ ¡£¡£¡£¾ÝϤ£¬£¬£¬ £¬£¬£¬£¬ £¬Ô±¹¤×Ô1999ÄêÒÔÀ´ÏòÕâЩ¹«Ë¾ÌṩµÄÓ×ÎҺͲÆÕþÐÅÏ¢¿ÉÄÜÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£ ¡£¡£¡£10ÔÂ6ÈÕ£¬£¬£¬ £¬£¬£¬£¬ £¬LockBit3.0½«SIRVAÔö³¤µ½ÁËÆäÍøÕ¾£¬£¬£¬ £¬£¬£¬£¬ £¬²¢ÓÚ11ÔÂ19ÈÕ¹«¿ªÁ˱»µÁÊý¾Ý¡£¡£¡£¡£¡£ ¡£¡£¡£BGRSÍøÕ¾×Ô9ÔÂ29ÈÕÆðÒ»Ïò´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£ ¡£¡£¡£


https://www.databreaches.net/canadian-government-announces-data-breach-urges-public-service-employees-to-take-action/


4¡¢Google³ÆZimbra·ì϶CVE-2023-37580±»4¸öÍÅ»ïÀûÓÃ


11ÔÂ16ÈÕ£¬£¬£¬ £¬£¬£¬£¬ £¬Google TAGÅû¶ÁË4ÆðÀûÓÃZimbraÖеÄXSS·ì϶£¨CVE-2023-37580£©µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ ¡£¡£¡£µÚÒ»´Î»î¶¯²úÉúÓÚ6Ôµף¬£¬£¬ £¬£¬£¬£¬ £¬Õë¶ÔµÄÊÇÏ£À°Ä³µ±¾Ö»ú¹¹£¬£¬£¬ £¬£¬£¬£¬ £¬·¢ÏÖ·ì϶ºóZimbraÔÚGitHubÉÏÍÆËÍÁËÒ»¸ö´¹Î£½¨¸´·¨Ê½¡£¡£¡£¡£¡£ ¡£¡£¡£Winter VivernÓÚ7ÔÂ11ÈÕÀûÓø÷ì϶¹¥»÷ÁËĦ¶û¶àÍߺÍÍ»Äá˹ȷµ±¾Ö»ú¹¹£¬£¬£¬ £¬£¬£¬£¬ £¬ZimbraÔÚ7ÔÂ13ÈÕ°ä²¼°²È«²¼¸æ½¨ÒéÓû§²ÉÈ¡»º½â´ëÊ©¡£¡£¡£¡£¡£ ¡£¡£¡£7ÔÂ20ÈÕ£¬£¬£¬ £¬£¬£¬£¬ £¬Î´ÖªºÚ¿Í¹¥»÷ÁËÔ½ÄÏijµ±¾Ö»ú¹¹£¬£¬£¬ £¬£¬£¬£¬ £¬ÎåÌìºóZimbra°ä²¼Á˸÷ì϶µÄ¹Ù·½²¹¶¡¡£¡£¡£¡£¡£ ¡£¡£¡£8ÔÂ25£¬£¬£¬ £¬£¬£¬£¬ £¬TAG·¢ÏÖÁ˵Ú4´ÎÀûÓø÷ì϶µÄ¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬£¬ £¬Õë¶Ô°Í»ù˹̹µ±¾Ö»ú¹¹¡£¡£¡£¡£¡£ ¡£¡£¡£


https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/


5¡¢8BaseÍÅ»ïͨ¹ýSmokeLoader·Ö·¢ÐµÄPhobos±äÌå


CiscoÔÚ11ÔÂ18Èճƣ¬£¬£¬ £¬£¬£¬£¬ £¬8Base½üÆÚµÄ»î¶¯ÓÐËùÔö³¤£¬£¬£¬ £¬£¬£¬£¬ £¬ËüʹÓÃÀÕË÷Èí¼þPhobosµÄ±äÌåºÍÆäËü¹«¿ª¿ÉÓõŤ¾ßÖ´Ðй¥»÷¡£¡£¡£¡£¡£ ¡£¡£¡£¸ÃÍÅ»ï´óÎÞÊýPhobos±äÌå¶¼ÊÇÓɺóÃÅSmokeLoader·Ö·¢µÄ¡£¡£¡£¡£¡£ ¡£¡£¡£ÔÚ8Base»î¶¯ÖУ¬£¬£¬ £¬£¬£¬£¬ £¬ËüÔÚ¼ÓÃܵÄpayloadÖÐǶÈëÁËÀÕË÷Èí¼þ×é¼þ£¬£¬£¬ £¬£¬£¬£¬ £¬¶øºó½«Æä½âÃܲ¢¼ÓÔØµ½SmokeLoader¹ý³ÌµÄÄÚ´æÖÓ×£¡£¡£¡£¡£ ¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬ £¬Phobos¶Ô1.5MBÒÔϵÄÎļþÆëÈ«¼ÓÃÜ£¬£¬£¬ £¬£¬£¬£¬ £¬¶Ô³¬¹ýãÐÖµµÄÎļþ²¿ÃżÓÃÜ£¬£¬£¬ £¬£¬£¬£¬ £¬ÒÔÌá¸ßËÙ¶È¡£¡£¡£¡£¡£ ¡£¡£¡£


https://blog.talosintelligence.com/deep-dive-into-phobos-ransomware/


6¡¢Avast°ä²¼2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


11ÔÂ16ÈÕ£¬£¬£¬ £¬£¬£¬£¬ £¬Avast°ä²¼ÁË2023ÄêµÚÈý¼¾¶ÈµÄÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£¡£µÚÈý¼¾¶È£¬£¬£¬ £¬£¬£¬£¬ £¬Avast¾ùÔÈÿÔÂÀ¹½ØµÄ¶ñÒâÈí¼þ¹¥»÷³¬¹ý10ÒڴΣ¬£¬£¬ £¬£¬£¬£¬ £¬ÍøÂçÍþв£¨ÓÈÆäÊÇÉ繤¹¥»÷ºÍ¶ñÒâ¸æ°×£©µÄ´ó·ùÔö³¤Íƶ¯ÁËÕâÒ»Ôö³¤¡£¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¶ÔÈËΪÖÇÄܵÄÀûÓÃÔڼӿ죬£¬£¬ £¬£¬£¬£¬ £¬ÓÈÆäÊÇÔÚÉî¶ÈαÔì½ðÈÚÚ¿Æ­»î¶¯ÖÓ×£¡£¡£¡£¡£ ¡£¡£¡£¸æ°×Èí¼þÏÔÖøÉý¼¶£¬£¬£¬ £¬£¬£¬£¬ £¬³ö¸ñÊÇÄÏÃÀ¡¢·ÇÖÞ¡¢¶«ÄÏÅ·ºÍ¶«ÑǵØÓò¡£¡£¡£¡£¡£ ¡£¡£¡£ÐÅÏ¢ÇÔÈ¡·¨Ê½µÄÍþвÔö³¤£¬£¬£¬ £¬£¬£¬£¬ £¬ÆäÖÐÎÚ¿ËÀ¼£¨44%£©¡¢ÃÀ¹ú£¨21%£©ºÍÓ¡¶È£¨16%£©µÄÔö·ù×îÏÔÖø¡£¡£¡£¡£¡£ ¡£¡£¡£RAT³ÖÐø³ÊÔö³¤Ç÷Ïò£¬£¬£¬ £¬£¬£¬£¬ £¬ÆÏÌÑÑÀ£¨148%£©¡¢²¨À¼£¨55%£©ºÍ˹Âå·¥¿Ë£¨43%£©µÈ¹úµÄÔö·ù×îÏÔÖø¡£¡£¡£¡£¡£ ¡£¡£¡£


https://decoded.avast.io/threatresearch/avast-q3-2023-threat-report/